Privacy Policy
Effective date: August 12, 2026
RoamFolio is an iOS app developed by Nossa ("Nossa," "we," "us," or "our") that helps you collect passport-style stamps for real-world cities and landmarks you visit. This Privacy Policy explains what information the app accesses, how it's used, and the choices you have. RoamFolio has no user accounts and no backend server of its own — the app is built to work almost entirely on your device, using Apple's own frameworks (CoreLocation, Photos, CloudKit, and on-device Apple Intelligence) for anything that needs your data.
1. Information We Collect
Location data
RoamFolio asks for location access ("while using the app") to show which stamping stations are nearby and to verify you're within range of one before letting you collect its stamp — 15 km for city stamps, 500 m for UNESCO/landmark stamps. Location is read live on your device to power this proximity check and the map views; RoamFolio does not track your location in the background, does not build a location history beyond the stamps you actually collect, and does not sell or share raw location data with anyone.
Photos
RoamFolio can read photo metadata in two different ways, depending on the feature:
- Adding a past trip ("Retro-Add"): when you pick a photo from your library (via Apple's system photo picker, which does not grant RoamFolio ongoing library access) or share one in from Google Photos, Files, or another app, RoamFolio reads that single photo's embedded GPS coordinate and capture date to match it against nearby stamping stations. The photo's image data itself is never decoded, stored, or uploaded — only the location/date metadata is used, momentarily, to find a match.
- Sending a postcard (RoamPost): to help you pick a photo taken near a stamp you've already collected, RoamFolio requests full photo library read access for this one feature. It scans your library's location metadata to surface nearby matches; a photo you actively choose becomes part of a postcard you send — see "Postcards and Friends" below for how that's stored and shared.
Camera
The camera is used only to scan a friend's RoamPost QR code so you can connect with them. RoamFolio does not otherwise access the camera and does not store camera frames or images from this scan.
Stamps you collect
The stations you've stamped and the dates you collected them are stored on your device and backed up to your own private iCloud account (via Apple's CloudKit) so they sync across your own devices. This data is private to your iCloud account — RoamFolio has no server that stores or has access to it.
Name and optional demographics
During setup, you can enter a display name (used only for the in-app greeting and editable anytime) and optionally a birth year and gender, which are used solely for aggregate, anonymous product analytics. All three fields are optional and can be skipped entirely; your display name is never sent to our analytics provider.
Sign in with Apple, Friends, and Postcards
Connecting with friends and sending postcards (RoamPost) is optional and requires signing in with Apple. We store the opaque identifier Apple provides, plus a randomly generated friend code, in Apple's CloudKit — not on a RoamFolio server. When you add a friend (by entering their code or scanning their QR code), a record of that connection is created in CloudKit. When you send a postcard, its artwork (built from your chosen photo and stamp) is stored in a private, per-recipient CloudKit share that only you and that specific friend can access.
Usage analytics
We use TelemetryDeck, a privacy-focused analytics service, to understand how people use RoamFolio — which screens are visited, how many stamps are collected and from which flow, whether nearby stations were found during a search, and non-identifying error events when something fails. TelemetryDeck does not use advertising identifiers, does not track you across other apps or websites, and does not require an App Tracking Transparency prompt because it doesn't perform cross-app tracking.
2. How We Use Information
- To show you stamping stations near your current location and let you collect them.
- To match a photo's embedded location/date against nearby stations for retro-adding stamps.
- To back up and sync your collected stamps across your own devices via iCloud.
- To power optional social features — friend connections and postcard delivery — for users who choose to sign in.
- To generate on-device descriptions of places you've stamped using Apple Intelligence, entirely on your device (see below).
- To understand aggregate app usage and fix errors, via TelemetryDeck.
We do not use your information to serve third-party ads, and we do not sell your personal information.
3. On-Device AI Descriptions
When you open a stamp's detail card, RoamFolio can generate a short description of that place using Apple's on-device Foundation Models framework (part of Apple Intelligence, where available on your device). This generation happens entirely on your device — no data about the place or your stamp collection is sent to RoamFolio or any third party to produce it. If Apple Intelligence isn't available or enabled on your device, a short generic description is shown instead.
4. Data Storage and Syncing
RoamFolio does not operate its own backend server. Data that needs to persist beyond your device — collected stamps, friend connections, and postcards — is stored using Apple's CloudKit, inside your own iCloud account:
- Your private database: your collected stamps sync only to your own devices, tied to your Apple ID.
- A shared, per-recipient record: a postcard you send is placed in a CloudKit share scoped to you and the one friend you sent it to — not a public or queryable database.
- A small public record: friend connections and a pointer used to notify a recipient that a postcard is waiting are stored in CloudKit's public database, containing only what's needed to make that connection or delivery work (e.g., friend codes, a share link) — never postcard photo content.
If iCloud is unavailable or you're signed out, RoamFolio's core stamp-collecting features keep working fully offline using on-device storage; only cross-device sync and the optional Friends/Postcards features require iCloud.
5. Third-Party Services
| Service | Purpose | What it sees |
|---|---|---|
| Apple CloudKit / iCloud | Stores collected stamps, friend connections, and postcards | Whatever is described in "Data Storage and Syncing" above, governed by Apple's own privacy policy |
| Apple Sign in with Apple | Optional identity for Friends/Postcards | An opaque user identifier; no profile data is requested |
| Apple Foundation Models (on-device AI) | Generates stamp descriptions | Runs entirely on your device; nothing is transmitted |
| TelemetryDeck | Privacy-conscious usage analytics | Anonymous, aggregate usage signals (see "Usage analytics" above) |
6. Sharing With Other Users
RoamFolio has no public profiles or social feed. Information is only shared with another person when you take a deliberate action to connect with them:
- Sharing your 12-digit friend code or QR code shares that code (not your location or stamp history) with whoever you show it to.
- Sending a postcard shares that specific postcard's artwork, the stamped station's name, the date, and your display name with the one friend you sent it to.
7. Your Choices and Controls
- Permissions: Location, Photos, and Camera access can each be reviewed or revoked anytime in iOS Settings → Privacy & Security, or Settings → RoamFolio. Declining a permission simply disables the feature that needs it (e.g., without location access, nearby stations won't be found).
- Demographics: the optional birth year and gender fields can be skipped during setup and are never required to use the app.
- Sign-in and Friends: signing in with Apple, adding friends, and sending postcards are entirely optional; the core passport-stamping experience never requires it.
- Deleting your data: deleting the app removes all locally stored data. Because collected stamps and postcards live in your own iCloud account (not on a RoamFolio server), you can also remove RoamFolio's iCloud data via iOS Settings → [your name] → iCloud → Manage Account Storage.
8. Children's Privacy
RoamFolio is not directed at children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, please contact us using the details below so we can address it.
9. Data Retention
Stamps, friend connections, and postcards persist for as long as your iCloud account retains them, or until you delete the app / remove that data from iCloud yourself. Analytics signals sent to TelemetryDeck are anonymous and are not linked back to an individual identity we control.
10. Security
Because RoamFolio stores your data in your own iCloud account rather than a RoamFolio-operated server, it inherits Apple's iCloud security and encryption protections. Postcards are stored in per-recipient CloudKit shares rather than a publicly queryable database, so only the intended recipient can access them.
11. Changes to This Policy
If RoamFolio's data practices change materially — for example, if a future feature adds a new kind of data collection — we'll update this page and revise the effective date above.
12. Contact Us
Questions about this policy or how RoamFolio handles your data? Reach out at support@nossaapp.com.